CVE-2025-7507 Information

Description

The elink – Embed Content plugin for WordPress is vulnerable to Malicious Redirect in all versions up to and including 1.1.0. This is due to the plugin not restricting URLS that can be supplied through the elink shortcode. This makes it possible for authenticated attackers with Contributor-level access and above to supply an HTML file that can be leverged to redirect users to a malicious domain.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L

Reference

https://wordpress.org/plugins/elink-embed-content/ https://www.wordfence.com/threat-intel/vulnerabilities/id/bda249f7-07a9-47ba-bba4-85abd8f8a207?source=cve

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

CHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

LOW

Base Severity

6.4

CNNVD-202508-1827 (Published: 2025-08-15)

Share on: